Application Serial No.: 10/074,583 
Amendment and Response to August 21, 2006 Final Office Action 

AMENDMENTS TO THE CLAIMS 

This listing of claims will replace all prior versions, and listings, of claims in the 
application: 

1 . (Currently Amended) A computer-implemented method for managing risk 
related to a security risk event, the method comprising: 

receiving infomnation relating to a particular security risk event; 

automatically p rocessino. by a computer, the information received to associate 
the received Infomiation with a first set of risk variables related to the particular security 
risk event; 

defining a second set of risk variables related to the particular securitv risk event 
wherein the first set of risk variables and the second set of risk variables are different: 

associating a portion of the received infonnation related to the particular securitv 
risk event and not associated with the first set of risk variables with the second set of 
risk variables: and 

calculating a security level using the processed infonnation and a set of 
relationships established between the first set and second set of risk variables. 

2. (Previously Presented) The method of claim 1 wherein the security 
level comprises an indication of an amount of risk that a breach of security may occur 
relating to the particular security risk event. 

3. (Previously Presented) The method of claim 1 wherein the security 
level comprises a security confidence level indicative of how secure a particular facility 
can be made relative to the particular security risk event. 
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4. (Previously Presented) The method of claim 1 wherein the security 
level comprises a security confidence level of how secure a particular practice can be 
made relative to the particular security risk event. 

5. (Previously Presented) The method of claim 1 wherein the security 
level comprises a security maintenance level indicative of a level of security that should 
be maintained in relation to the particular security risk event. 

6. (Previously Presented) The method of claim 1 additionally comprising 
the step of: 

generating a suggested security measure according to the security level and 
processed information. 

7. (Original) The method of claim 6 additionally comprising the step of: 

storing the infomnation received, the security level and the suggested security 
measure. 

8. (Original) The method Of claim 6 additionally comprising the step of: 
receiving information relating to security measures executed; and 
generating a security diligence report. 

9. (Previously Presented) The method of daim 8 wherein the security 
diligence report comprises Inquiries made relating to the particular security risk event 
and security measures executed responsive to the security level. 

10. (Previously Presented) The method of claim 6 wherein the suggested 
security measure comprises physical protection of media containing infonnation relating 
to the particular security risk event. 
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1 1 . (Previously Presented) The method of claim 6, wherein the suggested 
security measure comprises physical protection of a facility associated with the 
particular security risk event. 

12. (Previously Presented) The method of claim 6, wherein the wherein 
the suggested security measure comprises physical protection of a building associated 
with a business transaction. 

1 3. (Currently Amended) The method of claim 6, wherein the suggested 
securitv measure a GBoB-comDrises notifying an authority regarding a potential breach of 
security. 

14. (0riginal) The method of claim 6 additionally comprising the step of: 

branding the suggested security measure according to the set of relationships 
between the risk variables. 

15. (Original) The method of claim 1 wherein level of analysis utilized in 
the calculation of the security level is rated according to a classification. 

16. (Previously Presented) The method of claim 1 wherein the calculation 
comprises a level of weighting associated with a category of risk variables. 

17. (Cunrently Amended) The method of claim 1 wherein the calculation 
comprises aggregating multiple weightings of the first and second sets of ri sk 
variables. 

1 8. (Currently Amended) The method of claim 1 wherein the calculation 
comprises a relationship algorithm that determines which of the first and second sets of 
risk variables affects others of the first and second sets of risk variables. 

19. (Previously Presented) The method of claim 1 wherein the calculation 
includes a relationship algorithm comprising how data including a first variable 
can affect a weighting for a second variable. 
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20. (Original) The method of claim 1 additionally comprising the step of: 
recalculating the security level responsive to new infomiation received. 

21 . (Previously Presented) The method of claim 1 additionally comprising 
the step of: 

recalculating the security level responsive to progression of a chronology of 
particular security risk events. 

22. (Cun'ently Amended) A computerized system for managing risk 
related to a particular security risk event, the system comprising: 

a computer server accessible with a system access device via a communications 
network; and 

executable software stored on the server and executable on demand, the 
software operative with the server to cause the system to: 

receive infonnatlon relating to the particular security risk event; 

automaticallv proces ss tructur e the information received to associate the received 
information with acoord i na to a first set of risk variables related to the oarticular securitv 
risk event: 

define a second set of risk variables related to the particular securitv risk event, 
wherein the first set of risk variables and the second set of risk variables are different: 

associate a portion of the received information related to the particular securitv 
risk event and not associated with the first set of risk variables with the second set of 

risk variables: a nd 

calculate a security level using the structured infonnation and a set of 
relationships established between the risk variables. 
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23. (Original) The computerized system of claim 22 wherein the data is 
gathered via an electronic feed. 

24. (Currently Amended) A computer-readable medium having computer 
executable program instmctions residing thereon, the computer-readable medium 
comprising : 

instructions to receive infomnation relating to a particular security risk event; 

instructions to s tructure a utomaticallv process t he information received according 
to associate the received infomnation with a first set of risk variable s related to the 
particular security risk event : 

instructions to define a second set of risk variables related to the particular 
security risk event, wherein the first set of risk variables and the second set of risk 
variables are different: 

instructions to associate a portion of the received information related to the 
particular security risk event and not associated with the first set of risk variables with 
the second set of risk variables: 

and 

instructions to calculate a security level using the structured infomiation and a 
set of relationships established between the risk variables. 

25 - 28. (Canceled) 
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